OpenSSH ¸ßΣÎó²îÀ´Ï®£¡×ðÁú¿­Ê±Ìṩ½â¾ö¼Æ»®

Ðû²¼Ê±¼ä 2024-07-03

7ÔÂ1ÈÕ £¬OpenSSH¹Ù·½¸üÐÂÁËÒ»¸ö±£´æÓÚOpenSSHÖеÄÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-6387£©¡£¸ÃÎó²îÓÉÓÚOpenSSH·þÎñÆ÷£¨sshd£©ÖеÄÐźŴ¦Öóͷ£³ÌÐò¾ºÕùÎÊÌâ £¬Î´¾­Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔʹÓôËÎó²îÔÚLinuxϵͳÉÏÒÔrootÉí·ÝÖ´ÐÐí§Òâ´úÂë¡£CVSSÏÖÔÚÆÀ·Ö8.1·Ö £¬ÇëÊÜÓ°ÏìµÄÓû§¾¡¿ì½ÓÄɲ½·¥¾ÙÐзÀ»¤¡£


ͼƬ1.png


ÏÖÔÚ¸ÃÎó²îPOC£¨¿´·¨ÑéÖ¤´úÂ룩ÒѹûÕæ £¬ËæÊ±±£´æ±»ÍøÂçºÚ²úʹÓþÙÐÐÍÚ¿óľÂíºÍ½©Ê¬ÍøÂçµÈ¹¥»÷ÐÐΪµÄΣº¦¡£¸ÃÎó²îµÄ×ÛºÏÆÀ¼¶Îª¡°¸ßΣ¡±¡£


Îó²î³ÉÒò


CVE-2024-6387ÊÇOpenSSH·þÎñÖеÄÒ»¸öÑÏÖØÎó²î £¬Ó°Ïì»ùÓÚglibcµÄLinuxϵͳ¡£¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÔÚÎÞÐèÈÏÖ¤µÄÇéÐÎÏ £¬Í¨¹ý¾ºÌ¬Ìõ¼þÔ¶³ÌÖ´ÐÐí§Òâ´úÂë¡£


ÈôÊǿͻ§¶ËδÔÚLoginGraceTime ÃëÄÚ£¨Ä¬ÈÏÇéÐÎÏÂΪ120Ãë £¬¾É°æOpenSSHÖÐΪ600Ã룩¾ÙÐÐÉí·ÝÑéÖ¤ £¬ÔòsshdµÄSIGALRM´¦Öóͷ£³ÌÐò½«±»Òì³ÌÐòÓà £¬µ«¸ÃÐźŴ¦Öóͷ£³ÌÐò»áŲÓÃÖÖÖÖ·Çasync-signal-safeµÄº¯Êý£¨ÀýÈçsyslog()£© £¬ÍþвÕß¿ÉʹÓøÃÎó²îÔÚ»ùÓÚglibcµÄLinuxϵͳÉÏÒÔrootÉí·ÝʵÏÖδ¾­Éí·ÝÑéÖ¤µÄÔ¶³Ì´úÂëÖ´ÐС£


ÐÞ¸´½¨Òé


1¡¢Éý¼¶²¹¶¡

ÏÖÔÚ¸ÃÎó²îÒѾ­ÐÞ¸´ £¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½OpenSSH 9.8p1 ÒÔÉϰ汾¡£ÏÂÔØÁ´½Ó£º

https://www.openssh.com/releasenotes.html


×ðÁú¿­Ê±½â¾ö¼Æ»®


½¨ÒéÒ»£º×ðÁú¿­Ê±Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳÉý¼¶×îа汾


1¡¢Â©É¨6075°æ±¾


×ðÁú¿­Ê±Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ6075°æ±¾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐзÇÊÚȨɨÃè £¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000573 £¬Éý¼¶°üÏÂÔØµØµã£ºhttps://venustech.download.venuscloud.cn/


ͼƬ2.jpg

Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î


2¡¢Â©É¨608XϵÁа汾


×ðÁú¿­Ê±Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ608XϵÁа汾ÒѽôÆÈÐû²¼Õë¶Ô¸ÃÎó²îµÄÉý¼¶°ü £¬Ö§³Ö¶Ô¸ÃÎó²î¾ÙÐзÇÊÚȨɨÃè £¬Óû§Éý¼¶±ê×¼Îó²î¿âºó¼´¿É¶Ô¸ÃÎó²î¾ÙÐÐɨÃ裺


608XϵÁа汾Éý¼¶°üΪÖ÷»ú²å¼þ°ü6080000126-S6080000127.svs©ɨ²å¼þ°üÏÂÔØµØµã£º

https://venustech.download.venuscloud.cn/


ͼƬ3.jpg

Éý¼¶ºóÒÑÖ§³Ö¸ÃÎó²î


3¡¢Â©É¨»ùÏߺ˲é


ͨ¹ý×ðÁú¿­Ê±Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ-ÉèÖú˲éÄ£¿é¶Ô¸ÃÎó²îÓ°ÏìµÄ openssh-server Èí¼þ°ü°æ±¾¾ÙÐлñÈ¡ £¬Ê¹ÓÃÖÇÄÜ»¯ÆÊÎöÑÐÅлúÖÆÑéÖ¤¸ÃÎó²îÊÇ·ñ±£´æ £¬ÈôÊDZ£´æ¸ÃÎó²î½¨Òé¸üе½Çå¾²°æ±¾¡£ÈçͼËùʾ£º


ͼƬ4.jpg

»ùÏߺ˲éÒÑÖ§³Ö¸ÃÎó²î¼ì²éÄÜÁ¦


ÇëʹÓÃ×ðÁú¿­Ê±Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳ²úÆ·µÄÓû§¾¡¿ìÉý¼¶µ½×îа汾 £¬ÊµÊ±¶Ô¸ÃÎó²î¾ÙÐмì²â £¬ÒԱ㾡¿ì½ÓÄÉÌá·À²½·¥¡£


½¨Òé¶þ£º×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨(ASM)ÅŲéÊÜÓ°Ïì×ʲú


×ðÁú¿­Ê±×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨ÊµÊ±ÊÕÂÞ²¢¸üÐÂÇ鱨ÐÅÏ¢ £¬¶ÔÈë¿â×ʲúÎó²îOpenSSH Ô¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-6387£©¾ÙÐÐÖÎÀí £¬ÈçͼËùʾ£º


ͼƬ5.jpg

Ç鱨ÖÎÀíÄ£¿éÒÑÈë¿âµÄOpenSSH Ô¶³Ì´úÂëÖ´ÐÐÎó²î


×ʲúÓëųÈõÐÔÖÎÀíÆ½Ì¨Æ¾Ö¤Ç鱨ÐÅÏ¢¸üеÄÎó²îÊÜÓ°ÏìʵÌ广ÔòÒÔ¼°ÏÖ³¡×ʲúÖÎÀíʵÀýµÄ°æ±¾ÐÅÏ¢¾ÙÐÐ×Ô¶¯»¯Åöײ £¬¿ÉµÚһʱ¼äÖÀÖÐÊܸÃÎó²îÓ°ÏìµÄ×ʲú £¬ÈçͼËùʾ£º


ͼƬ6.jpg

Ç鱨ÖÀÖеÄ×ʲúÐÅÏ¢


½¨ÒéÈý£º»ùÓÚÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨¾ÙÐйØÁªÆÊÎö


¿í´óÓû§¿ÉÒÔͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ £¬¾ÙÐйØÁªÕ½ÂÔÉèÖà £¬ÍŽáÏÖÕæÏàÐÎÖÐϵͳÈÕÖ¾ºÍÇå¾²×°±¸µÄ¸æ¾¯ÐÅÏ¢¾ÙÐÐÒ»Á¬¼à¿Ø £¬´Ó¶ø·¢Ã÷¡°OpenSSHÔ¶³Ì´úÂëÖ´ÐС±µÄÎó²îʹÓù¥»÷ÐÐΪ¡£


1£©ÔÚÌ©ºÏµÄƽ̨ÖÐ £¬Í¨¹ýųÈõÐÔ·¢Ã÷¹¦Ð§Õë¶Ô¡°OpenSSHÔ¶³Ì´úÂëÖ´ÐÐÎó²î£¨CVE-2024-6387£©¡±Îó²îɨÃèʹÃü £¬ÅŲéÖÎÀíÍøÂçÖÐÊÜ´ËÎó²îÓ°ÏìµÄÖ÷Òª×ʲú£»


ͼƬ7.jpg


2£©Æ½Ì¨¡°¹ØÁªÆÊÎö¡±Ä£¿éÖÐ £¬Ìí¼Ó¡°L2_OpenSSHÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá± £¬Í¨¹ý×ðÁú¿­Ê±¼ì²â×°±¸¡¢Ä¿µÄÖ÷»úϵͳµÈ×°±¸µÄ¸æ¾¯ÈÕÖ¾ £¬·¢Ã÷Íⲿ¹¥»÷ÐÐΪ£»


ͼƬ8.jpg


̫ͨ¹ýÎö¹æÔò×Ô¶¯½«L2_OpenSSHÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓõĿÉÒÉÐÐΪԴµØµãÌí¼Óµ½ÊÓ²ìÁÐ±í¡°¸ßΣº¦ÅþÁ¬¡±ÖÐ £¬×÷ΪÄÚ²¿Ç鱨Êý¾ÝʹÓã»


3£©Ìí¼Ó¡°L3_OpenSSHÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓÃÀֳɡ± £¬Ìõ¼þÈÕÖ¾Ãû³Æ¼´ÊÇ»ò°üÀ¨¡°L2_OpenSSHÔ¶³Ì´úÂëÖ´ÐÐÎó²îʹÓá± £¬¹¥»÷Ч¹û¼´ÊÇ¡°¹¥»÷Àֳɡ± £¬Ä¿µÄµØµãÒýÓÃ×ʲúÎó²î»òÔ´µØµãÆ¥ÅäÍþвÇ鱨 £¬´Ó¶øÌáÉý¹ØÁª¹æÔòµÄÖÃÐŶÈ¡£


ͼƬ9.jpg


½¨ÒéËÄ£ºATT&CK¹¥»÷Á´ÌõÆÊÎöÓëSOAR´¦Öóͷ£½¨Òé


1¡¢ATT&CK¹¥»÷Á´ÆÊÎö


ƾ֤¶ÔCVE-2024-6387Îó²îµÄ¹¥»÷ʹÓÃÀú³Ì¾ÙÐÐÆÊÎö £¬¹¥»÷Á´Éæ¼°¶à¸öATT&CKÕ½ÊõºÍÊÖÒÕ½×¶Î £¬ÁýÕÖµÄTTP°üÀ¨£º

TA0001³õʼ»á¼û£º  T1190ʹÓÃÃæÏò¹«ÖÚµÄÓ¦ÓóÌÐò

TA0002Ö´ÐУº        T1059ÏÂÁîºÍ¾ç±¾Ú¹ÊÍÆ÷

TA0004ȨÏÞÌáÉý£º  T1548ÀÄÓÃÌáȨ¿ØÖÆ»úÖÆ


2¡¢ ´¦Öóͷ£¼Æ»®½¨æÅºÍSOAR¾ç±¾±àÅÅ


ͼƬ10.jpg


ͨ¹ýÌ©ºÏÇå¾²ÖÎÀíºÍÌ¬ÊÆ¸Ð֪ƽ̨ÄÚÖÃSOAR×Ô¶¯»¯»ò°ë×Ô¶¯»¯±àÅÅÁª¶¯ÏìÓ¦´¦Öóͷ£ÄÜÁ¦ £¬Õë¶Ô¸ÃÎó²îʹÓõĸ澯ÊÂÎñ±àÅž籾 £¬¾ÙÐÐ×Ô¶¯»¯´¦Öóͷ£



¹ØÓÚ±±Ú¤Êý¾ÝʵÑéÊÒ


±±Ú¤Êý¾ÝʵÑéÊÒã¡ÊØÒÔÓû§ÐèÇóΪÖÐÐÄ¡¢ÖªÊ¶¸³ÄܲúƷΪĿµÄµÄ½¹µãÀíÄî £¬×¨×¢ÓÚÉîÈëÑо¿ºÍ¿ª·¢ÍøÂç¿Õ¼äÇå¾²µÄ»ù´¡ÖªÊ¶¡£Í¨¹ýÕûºÏÍþвºÍÎó²îÇ鱨¡¢ÍøÂç¿Õ¼ä×ʲúÒÔ¼°ÔÆÇå¾²¼à²âÊý¾Ý £¬Öƶ©ÖÜÈ«µÄÇå¾²ÆÊÎö·À»¤Õ½ÂÔ £¬ÒÔÖª×ãÓû§ÏÖʵ³¡¾°µÄÐèÇó¡£Í¬Ê± £¬ÖÂÁ¦ÓÚ¹¹½¨×Ô¶¯»¯ÊÓ²ìºÍ´¦Öóͷ£ÏìÓ¦²½·¥ £¬Ðγɳ¡¾°»¯¡¢½á¹¹»¯µÄ֪ʶ¹¤³Ìϵͳ £¬ÎªÖÖÖÖÇå¾²²úÆ·¡¢Æ½Ì¨ºÍÇå¾²ÔËÓªÌṩǿʢµÄ֪ʶ¸³ÄÜ¡£